CVE-2025-5125: Howardehrenberg Custom Post Carousels With Owl
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it.
Affected products
- Howardehrenberg Custom Post Carousels With Owl: before 1.4.12 (fixed in 1.4.12)
Published 2025-06-20. Last modified 2026-06-17.